THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2wxc-x7rj-hg8f (high) — asyncssh has SCP Path Traversal to Arbitrary File Write

[GHSA] GHSA-2wxc-x7rj-hg8f (high) — asyncssh has SCP Path Traversal to Arbitrary File Write

medgithub_advisoriesPublished 2026-08-26

GHSA-2wxc-x7rj-hg8f Severity: high CVE: CVE-2026-54591

asyncssh has SCP Path Traversal to Arbitrary File Write

| | | |---|---| | Product | asyncssh (all versions through 2.23.0) | | Related | CVE-2019-6111 (same class in OpenSSH) | | Fix | AsyncSSH 2.23.1 |

A malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing `../` traversal se

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2wxc-x7rj-hg8f